codex-issue-waves
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is largely purpose-aligned for GitHub/Codex orchestration and uses official service/tooling paths, but it grants an AI agent substantial autonomous control over code changes, reviews, pushes, merges, and potentially deployment. The biggest concerns are autonomous real-world repo actions, prompt-injection exposure from issues/diffs, and the transitive trust dependency on an unseen sub-skill.
Confidence: 87%Severity: 72%
Audit Metadata